Wiz’s CosmosEscape Exposed Every Azure Cosmos DB, CISA Sounds Alarm on Water-System PLC Attacks, and Teams Vishing Drops Chaos Ransomware

This brief covers cyber security developments from the trailing ~48 hours (July 30 – August 1, 2026). Every item below was verified against its primary source — vendor advisory, government alert, or original research — before inclusion.

CosmosEscape: Wiz researchers could have taken over every Azure Cosmos DB database

Wiz Research · July 30, 2026

Wiz Research disclosed CosmosEscape, a critical vulnerability chain in Azure Cosmos DB’s Gremlin API. By escaping the Gremlin query sandbox via .NET reflection, researchers gained code execution on the multi-tenant DB Gateway and extracted a platform-wide signing secret they dubbed the “Cosmos Master Key” — capable of retrieving the primary key of any Cosmos DB account across all tenants, regions, and API flavors. No CVE ID or CVSS score was assigned to this cloud-service flaw. Microsoft deployed a hotfix within 48 hours of the November 2025 report, completed a permanent architectural fix across all regions in July 2026, and found no evidence of exploitation or customer data access. No customer action is required.

“It was a platform-wide key that could retrieve the primary key for any Cosmos DB account on the service, all through publicly accessible endpoints.” — Wiz Research

Source: Wiz Research blog · SecurityWeek

CISA urges water utilities to pull exposed PLCs offline after coordinated attacks on 30+ Minnesota systems

CISA · July 30, 2026

CISA issued an alert warning of a significant increase in threat activity targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. The alert follows a coordinated cyberattack on more than 30 Minnesota community water systems that state officials suspect may be linked to Iran; attackers changed PLC passwords to lock out operators, modified IP addresses to disconnect devices, and disrupted operations, forcing some utilities to switch to manual operation. CISA specifically flagged undocumented cellular modems as a common blind spot and pointed Rockwell Automation MicroLogix 1400 owners to vendor recovery guidance. Censys estimates more than 4,100 Rockwell/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts are currently reachable from the public internet.

“CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.” — CISA alert, July 30, 2026

Source: CISA alert · BleepingComputer

Sophos: Microsoft Teams vishing campaign STAC4749 deployed Chaos ransomware in under 17 hours

Sophos · July 30, 2026

Sophos detailed STAC4749, a Teams voice-phishing campaign that targeted dozens of North American organizations between February and June 2026 — roughly 95% in Canada (50%) and the U.S. (44%). Operators posed as IT helpdesk staff from “.top” domains like info-secure[.]top, talked victims into Quick Assist or RemSupp remote sessions, then deployed a custom loader, a Python backdoor, and Golang C2 implants with pinned certificates. At least three intrusions ended in Chaos ransomware deployment; in one case, initial access to encryption took less than 17 hours. Most scam calls lasted just two to two-and-a-half minutes.

“Given the short interval between initial access and encryption, Sophos analysts assess with high confidence that STAC4749 was a financially motivated operation that either directly deployed ransomware or coordinated with affiliates.” — Sophos

Source: Sophos threat research · BleepingComputer

Still developing

Cisco patches actively exploited Secure FMC zero-day CVE-2026-20316; KEV deadline was August 1

Cisco / CISA · July 29, 2026

Cisco released patches for CVE-2026-20316, a static-credential vulnerability in Secure Firewall Management Center that lets a remote, unauthenticated attacker log into devices using default credentials for a low-privilege account and access sensitive data. Cisco rates it high severity, confirmed active exploitation observed in July, and published indicators of compromise; the flaw can be chained with other FMC bugs to escalate privileges. CISA added it to the Known Exploited Vulnerabilities catalog on July 29 with a remediation deadline of August 1 for federal agencies. Discovery is credited to a Horizon3.ai researcher.

“If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.” — Cisco security advisory

Source: Cisco advisory · CISA KEV alert · SecurityWeek

Russian group TA488 exploits Exchange OWA flaw CVE-2026-42897 to plant OWAReaper implant

Proofpoint · July 29, 2026

Proofpoint reported that Russia-aligned TA488 (Void Blizzard / Laundry Bear) began a campaign on July 22 exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access that Microsoft patched in June 2026, against US and European government entities plus telecom, financial, hospitality, and aerospace targets. Opening a crafted email is enough to execute OWAReaper, a browser-resident JavaScript implant that steals autofill credentials and OAuth tokens, grants mailbox-wide folder permissions to the tenant’s “Default” user, and persists in OWA settings and the offline message cache. Campaign infrastructure dates to March 2026 — two months before Microsoft’s out-of-band patch — suggesting possible zero-day use.

“This persistent access lives on the server-side and requires deliberate removal from the Exchange server; credential rotation and even full re-imaging of the targeted user’s device will not evict the actor.” — Proofpoint Threat Research

Source: Proofpoint threat research · NVD entry · BleepingComputer


This brief covers the trailing ~48 hours (July 30 – August 1, 2026). Primary sources: Wiz Research, CISA Alert (Jul 30), Sophos, Cisco PSIRT, CISA KEV (Jul 29), Proofpoint.

Leave a Reply